arrow_backPazmo

What Pazmo covers

Pazmo covers what it can detect online, lets you self-report what it can't, and guides the rest. It never determines or certifies compliance — this shows readiness coverage only.

ISO/IEC 27001:2022

Control-mapped

The spine other frameworks crosswalk to.

Detected now
22checks
You self-report
15items
Via connections
4areas
Guidance
3areas

Coming via connections (GitHub / cloud)

  • ·Source-code access & secure coding (A.8.4 / A.8.28)
  • ·Technical vulnerability mgmt — dependencies/CVEs (A.8.8)
  • ·Change management — branch protection (A.8.32)
  • ·Logging & monitoring (A.8.15 / A.8.16)

Pazmo guides (process controls)

  • ·Security policy, asset inventory, supplier security (A.5)
  • ·Risk assessment & treatment process
  • ·Secure SDLC & data-leakage prevention (A.8.25–A.8.31)

Out of scope: Physical controls (A.7) and personnel/hiring checks.

SOC 2 (Trust Services Criteria)

Control-mapped

Common Criteria mostly crosswalks onto the ISO spine.

Detected now
10checks
You self-report
15items
Via connections
2areas
Guidance
1areas

Coming via connections (GitHub / cloud)

  • ·Logical access & change management (CC6 / CC8)
  • ·Vulnerability detection & monitoring (CC7)

Pazmo guides (process controls)

  • ·Control environment, risk assessment, vendor management (CC1–CC5, CC9)

Out of scope: Physical security and HR processes.

GDPR

Crosswalk pending

Article-based; transport encryption & access map to Art. 32 readiness.

Detected now
0checks
You self-report
15items
Via connections
1areas
Guidance
1areas

Coming via connections (GitHub / cloud)

  • ·Access control & encryption-at-rest evidence (Art. 32)

Pazmo guides (process controls)

  • ·Lawful basis, data-subject rights, records of processing, DPA with vendors

Out of scope: Legal determinations and organizational data-governance.

ISO/IEC 27701 (Privacy)

Crosswalk pending

Extension of the ISO 27001 spine.

Detected now
0checks
You self-report
15items
Via connections
0areas
Guidance
1areas

Pazmo guides (process controls)

  • ·PII processing controls extending ISO 27001 — mostly policy/process

Out of scope: Privacy governance and legal roles.

HIPAA Security Rule

Crosswalk pending

Scope-gated; relevant only if you handle PHI.

Detected now
0checks
You self-report
15items
Via connections
1areas
Guidance
1areas

Coming via connections (GitHub / cloud)

  • ·Audit logging & access controls (Technical Safeguards)

Pazmo guides (process controls)

  • ·Administrative safeguards — policies, training, BAAs

Out of scope: Physical safeguards and workforce procedures.

AI App Safety

Crosswalk pending

Not a formal audit framework.

Detected now
0checks
You self-report
0items
Via connections
1areas
Guidance
1areas

Coming via connections (GitHub / cloud)

  • ·AI app static checks — prompt/output handling (Phase 3)

Pazmo guides (process controls)

  • ·Model usage policy, output validation, abuse monitoring

Out of scope: No formal control catalogue exists; handled as guidance + static checks.

EN 18031 (Radio equipment)

Crosswalk pending

Scope-gated; shown only when declared.

Detected now
0checks
You self-report
0items
Via connections
0areas
Guidance
0areas

Out of scope: Device/firmware standard — largely not applicable to web/SaaS.

Readiness coverage only — Pazmo does not determine or certify compliance.